- Description
- Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Drupal core allows Cross-Site Scripting (XSS).This issue affects Drupal core: from 8.0.0 before 10.3.14, from 10.4.0 before 10.4.5, from 11.0.0 before 11.0.13, from 11.1.0 before 11.1.5.
- Source
- mlhess@drupal.org
- NVD status
- Analyzed
CVSS 3.1
- Type
- Secondary
- Base score
- 5.4
- Impact score
- 2.7
- Exploitability score
- 2.3
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
- Severity
- MEDIUM
- Hype score
- Not currently trending
🔴 Drupal, Cross-Site Scripting (XSS), #CVE-2025-31675 (Critical) https://t.co/8bvpVUc8fT
@dailycve
3 Jun 2025
19 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2025-31675 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Drupal core allows Cross-Site Scripting (XSS).This issue … https://t.co/l71UqGY5oM
@CVEnew
31 Mar 2025
236 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
[
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:drupal:drupal:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5203ABED-9A31-41A8-9A2E-51114DB3806C",
"versionEndExcluding": "10.3.14",
"versionStartIncluding": "8.0.0"
},
{
"criteria": "cpe:2.3:a:drupal:drupal:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "3A7811E7-6793-4CE0-B866-B72B59415A5F",
"versionEndExcluding": "10.4.5",
"versionStartIncluding": "10.4.0"
},
{
"criteria": "cpe:2.3:a:drupal:drupal:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "CDD587C1-9A62-4104-92B3-65B6E04BDC95",
"versionEndExcluding": "11.0.13",
"versionStartIncluding": "11.0.0"
},
{
"criteria": "cpe:2.3:a:drupal:drupal:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "13E1698C-D69F-4B55-B7B9-1E0F0A7888D6",
"versionEndExcluding": "11.1.5",
"versionStartIncluding": "11.1.0"
}
],
"operator": "OR"
}
]
}
]